This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

CryptoLocker encrypted all my docs, need help [Closed]

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Almost all docs (.doc, .pdf, .xls) from my PC are encrypted, also virus added extension .ecc. I tried https://www.decryptcryptolocker.com/ but it would not recognize any of my documents as been infected by CryptoLocker. I ran FarBar and both attachments are here. I am running this computer in Safe mode with Networking, as some infections are still active. Please, help.

Hello ustal, welcome to WhatTheTech's Malware Removal forum!
 
My name is Adam. I will be assisting you with your malware-related problems.
If you would allow me to call you by your first name I would prefer that.  :)
 
======================================================
 
Please read through the points below to ensure this process moves as quickly and efficiently as possible.

  • Ensure you read through my instructions thoroughly, and carry out each step in the order specified.
  • Please do not run any tools or take any steps other than those I provide for you. Independent efforts may make matters worse, and will affect my ability in providing the best set of instructions for you.
  • Please backup important files before proceeding with my instructions. Malware removal can be unpredictable at times.   
  • If you come across any issues whilst following my instructions, please stop and inform me of the issue in as much detail as possible. Please do not hesitate to ask before proceeding.
  • Topics are locked if no response is made after 4 days. Please inform me if you require additional time to complete my instructions.
  • I will notify you when I believe your computer is free of malware. Please bear in mind, absence of symptoms does not necessarily correlate to absence of malware, so please wait until the "All Clean". 
  • Ensure you are following this topic. Click [external image: etYzdbu.png] at the top of the page. 

======================================================
 
Your files have not been encrypted by CryptoLocker - this file encrypter has been dead for a year, meaning the decryptcryptolocker site is of little use. 
 
From the flags in your log, your files appear to have been encrypted by TeslaCrypt. However, this is somewhat of a strange case. There are two distinguishable variants of TeslaCrypt - going by the flags, you appear to have a hybrid of both, which may unfortunately complicate matters further. 
 
The good news is that there is a decrypter for TeslaCrypt - Cisco's decrypter. However, this decrypter only works with the first variant, not the second. So I don't know if you're going to be successful in decrypting your files or not. We do have other options to explore if the decrypter fails. 
 
In addition to your encrypted files, your computer is badly compromised - with Poweliks (remants), Zbot, Bedep, Fleercivet and Kovter. These types of malware are severe. I strongly recommend changing passwords and account details using a clean computer.
 
——
 
Before you consider attempting decryption of your files, I recommend we first clean the computer. Due to the nature of the malware on your computer, and their propensity to download file encrypting ransomware, you may risk your decrypted files being re-encrypted if we do not clean the computer first. 
 

However, the decision is ultimately yours. 

If you wish to clean your computer first, please do the following:
 
Boot into Normal Mode, and do the following. If you are unable to carry out the instructions in Normal Mode, boot back into Safe Mode (not with Networking). 
 
Do you recognise the files (and folder) in the spoiler below? Most are encrypted. 
Do not extract (open) any of the "Attachments" files.
2015-05-13 18:41 - 2015-05-13 18:41 - 00000059 _____ () C:\Users\Robert Buss\Desktop\need.txt
2015-04-27 19:42 - 2015-04-27 19:42 - 00303732 _____ () C:\Users\Robert Buss\Downloads\Attachments (3).zip
2015-04-27 19:36 - 2015-04-27 19:36 - 06703046 _____ () C:\Users\Robert Buss\Downloads\Attachments (2).zip
2015-04-27 18:20 - 2015-04-27 18:20 - 01803717 _____ () C:\Users\Robert Buss\Downloads\Attachments (1).zip
2015-04-27 18:18 - 2015-04-27 18:17 - 01369479 _____ () C:\Users\Robert Buss\Downloads\Attachments.zip
2015-04-15 16:07 - 2015-04-20 17:09 - 00000000 ____D () C:\Users\Robert Buss\Documents\Attachments-6
2015-04-15 16:59 - 2015-04-20 18:39 - 00253588 _____ () C:\Users\Robert Buss\Downloads\Attachments(5).zip.ecc
2015-04-15 16:06 - 2015-04-20 18:39 - 00253588 _____ () C:\Users\Robert Buss\Downloads\Attachments(4).zip.ecc
2015-04-20 18:39 - 2015-02-14 11:22 - 03963060 _____ () C:\Users\Robert Buss\Downloads\Attachments(3).zip.ecc
2015-04-20 18:39 - 2014-12-02 14:20 - 00035300 _____ () C:\Users\Robert Buss\Downloads\Attachments(2).zip.ecc
2015-04-20 18:39 - 2014-12-02 14:19 - 00035300 _____ () C:\Users\Robert Buss\Downloads\Attachments(1).zip.ecc
2015-04-20 18:39 - 2014-03-22 11:03 - 17161828 _____ () C:\Users\Robert Buss\Downloads\attachment (1).zip.ecc
2015-04-20 18:39 - 2014-03-02 11:53 - 17161828 _____ () C:\Users\Robert Buss\Downloads\attachment.zip.ecc
2015-04-20 18:39 - 2014-01-29 13:03 - 11756932 _____ () C:\Users\Robert Buss\Downloads\Attachments (7).zip.ecc
2015-04-20 18:39 - 2014-01-29 11:49 - 12633844 _____ () C:\Users\Robert Buss\Downloads\Attachments (6).zip.ecc
2015-04-20 18:39 - 2013-11-26 18:02 - 00432244 _____ () C:\Users\Robert Buss\Downloads\Attachments (5).zip.ecc
2015-04-20 18:39 - 2013-08-23 17:32 - 00179716 _____ () C:\Users\Robert Buss\Downloads\Attachments (4).zip.ecc
2015-04-20 18:39 - 2013-07-20 08:59 - 00015444 _____ () C:\Users\Robert Buss\Downloads\Attachments (3).zip.ecc
2015-04-20 18:39 - 2013-07-20 08:57 - 00015444 _____ () C:\Users\Robert Buss\Downloads\Attachments (2).zip.ecc
2015-04-20 18:39 - 2013-06-22 12:20 - 02925476 _____ () C:\Users\Robert Buss\Downloads\Attachments (1).zip.ecc
2015-04-20 18:39 - 2013-06-03 11:37 - 02925476 _____ () C:\Users\Robert Buss\Downloads\Attachments.zip.ecc
STEP 1
[external image: xlK5Hdb.png] Farbar Recovery Scan Tool (FRST) Script

  • Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type Notepad and click OK.
  • Copy the entire contents of the codebox below and paste into the Notepad document.
    start
    CreateRestorePoint:
    HKLM-x32\…\Run: [] => [X]
    HKU\S-1-5-21-4221278862-339456626-841341803-1001\…\Run: [WinSystem] => C:\Windows\syswow64\windowspowershell\v1.0\powershell.exe [452608 2009-07-13] (Microsoft Corporation)
    HKU\S-1-5-21-4221278862-339456626-841341803-1001\…A8F59079A8D5}\localserver32:  <==== ATTENTION!
    HKU\S-1-5-18\…\Run: [WinSystem] => C:\Windows\syswow64\windowspowershell\v1.0\powershell.exe [452608 2009-07-13] (Microsoft Corporation)
    Toolbar: HKU\S-1-5-21-4221278862-339456626-841341803-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
    Toolbar: HKU\S-1-5-21-4221278862-339456626-841341803-1001 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} -  No File
    FF SearchPlugin: C:\Users\Robert Buss\AppData\Roaming\Mozilla\Firefox\Profiles\rlfmg9nt.default\searchplugins\HELP_RESTORE_FILES.txt [2015-04-21]
    C:\Program Files (x86)\VideoDownloadConverter_4z
    C:\Program Files (x86)\Common Files\AVG Secure Search
    File: C:\windows\system32\Drivers\psaftshf.sys
    Folder: C:\Users\Robert Buss\AppData\Local\{234E4DF9-E803-4C43-A642-140DE08BECE4}
    Folder: C:\Users\Robert Buss\AppData\Local\{D3FAD453-A290-4C44-B353-147DF9EA8E51}
    Folder: C:\Users\Robert Buss\AppData\Local\{33EF1A96-CAAA-4AF3-8D94-23351D1C8978}
    Folder: C:\Users\Robert Buss\AppData\Local\{A29DF038-E3C3-4CB4-B459-A1ECAC41CD52}
    Folder: C:\Users\Robert Buss\AppData\Local\{81C58831-66FC-43E9-BBFA-0EF4DE905BE0}
    Folder: C:\Users\Robert Buss\AppData\Local\{25246F23-BFE0-4F22-A19D-4A33A03E36A5}
    Folder: C:\Users\Robert Buss\AppData\Local\{1F4EE87E-D44E-44E8-990C-7B494CB75F31}
    Folder: C:\Users\Robert Buss\AppData\Local\{8F78472B-EFE3-4811-B550-A5F8DDABC0C1}
    2015-05-05 13:51 - 2015-05-05 13:51 - 00000000 ____D () C:\ProgramData\Windows Genuine Advantage
    2015-05-04 13:54 - 2015-05-13 09:05 - 00000000 ____D () C:\Users\Robert Buss\AppData\Local\umyc
    2015-05-02 07:25 - 2015-05-04 13:58 - 00000000 ____D () C:\Users\Robert Buss\AppData\Local\yviwag
    2015-04-21 13:48 - 2015-04-21 13:54 - 02304678 _____ () C:\Users\Robert Buss\Desktop\HeLP_ReSTORe_FILeS.bmp
    2015-04-21 13:48 - 2015-04-21 13:54 - 00001599 _____ () C:\Users\Robert Buss\Desktop\CryptoLocker.lnk
    2015-04-21 09:52 - 2015-04-21 09:52 - 00002674 _____ () C:\windows\HELP_RESTORE_FILES.txt
    2015-04-21 09:40 - 2015-04-21 09:40 - 00002674 _____ () C:\windows\Tasks\HELP_RESTORE_FILES.txt
    2015-04-21 09:36 - 2015-04-21 09:40 - 00002674 _____ () C:\windows\SysWOW64\HELP_RESTORE_FILES.txt
    2015-04-21 09:31 - 2015-04-21 09:37 - 00002674 _____ () C:\windows\SysWOW64\Drivers\HELP_RESTORE_FILES.txt
    2015-04-21 09:28 - 2015-04-21 09:28 - 00002674 _____ () C:\windows\system\HELP_RESTORE_FILES.txt
    2015-04-21 09:17 - 2015-04-21 09:17 - 00002674 _____ () C:\windows\Minidump\HELP_RESTORE_FILES.txt
    2015-04-20 17:08 - 2015-04-21 13:54 - 00001362 _____ () C:\Users\Robert Buss\Desktop\HELP_RESTORE_FILES.txt
    2015-04-20 05:45 - 2015-04-21 13:36 - 00002674 _____ () C:\Users\Robert Buss\AppData\Roaming\HELP_RESTORE_FILES.txt
    2015-04-20 05:45 - 2015-04-21 10:19 - 00002674 _____ () C:\Users\Public\HELP_RESTORE_FILES.txt
    2015-04-20 05:44 - 2015-04-21 10:19 - 00002674 _____ () C:\Users\Public\Downloads\HELP_RESTORE_FILES.txt
    2015-04-20 05:44 - 2015-04-21 10:19 - 00002674 _____ () C:\Users\McAfeeMVSUser\HELP_RESTORE_FILES.txt
    2015-04-20 05:44 - 2015-04-21 10:19 - 00002674 _____ () C:\Users\McAfeeMVSUser\AppData\Roaming\HELP_RESTORE_FILES.txt
    2015-04-20 05:44 - 2015-04-21 10:19 - 00002674 _____ () C:\Users\McAfeeMVSUser\AppData\HELP_RESTORE_FILES.txt
    2015-04-20 05:44 - 2015-04-21 10:19 - 00002674 _____ () C:\Users\Default\HELP_RESTORE_FILES.txt
    2015-04-20 05:44 - 2015-04-21 10:19 - 00002674 _____ () C:\Users\Default\Downloads\HELP_RESTORE_FILES.txt
    2015-04-20 05:44 - 2015-04-21 10:19 - 00002674 _____ () C:\Users\Default\Documents\HELP_RESTORE_FILES.txt
    2015-04-20 05:44 - 2015-04-21 10:19 - 00002674 _____ () C:\Users\Default\Desktop\HELP_RESTORE_FILES.txt
    2015-04-20 05:44 - 2015-04-21 10:19 - 00002674 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HELP_RESTORE_FILES.txt
    2015-04-20 05:44 - 2015-04-21 10:19 - 00002674 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\HELP_RESTORE_FILES.txt
    2015-04-20 05:44 - 2015-04-21 10:19 - 00002674 _____ () C:\Users\Default\AppData\Roaming\HELP_RESTORE_FILES.txt
    2015-04-20 05:44 - 2015-04-21 10:19 - 00002674 _____ () C:\Users\Default\AppData\Local\HELP_RESTORE_FILES.txt
    2015-04-20 05:44 - 2015-04-21 10:19 - 00002674 _____ () C:\Users\Default\AppData\HELP_RESTORE_FILES.txt
    2015-04-20 05:44 - 2015-04-21 10:19 - 00002674 _____ () C:\Users\Default User\Downloads\HELP_RESTORE_FILES.txt
    2015-04-20 05:44 - 2015-04-21 10:19 - 00002674 _____ () C:\Users\Default User\Documents\HELP_RESTORE_FILES.txt
    2015-04-20 05:44 - 2015-04-21 10:19 - 00002674 _____ () C:\Users\Default User\Desktop\HELP_RESTORE_FILES.txt
    2015-04-20 05:44 - 2015-04-21 10:19 - 00002674 _____ () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HELP_RESTORE_FILES.txt
    2015-04-20 05:44 - 2015-04-21 10:19 - 00002674 _____ () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\HELP_RESTORE_FILES.txt
    2015-04-20 05:44 - 2015-04-21 10:19 - 00002674 _____ () C:\Users\Default User\AppData\Roaming\HELP_RESTORE_FILES.txt
    2015-04-20 05:44 - 2015-04-21 10:19 - 00002674 _____ () C:\Users\Default User\AppData\Local\HELP_RESTORE_FILES.txt
    2015-04-20 05:44 - 2015-04-21 10:19 - 00002674 _____ () C:\Users\Default User\AppData\HELP_RESTORE_FILES.txt
    2015-04-20 05:39 - 2015-04-21 10:19 - 00002674 _____ () C:\Users\Public\Documents\HELP_RESTORE_FILES.txt
    2015-04-20 05:39 - 2015-04-21 10:19 - 00002674 _____ () C:\Users\Public\Desktop\HELP_RESTORE_FILES.txt
    2015-04-20 02:21 - 2015-04-20 18:43 - 00002674 _____ () C:\Users\HELP_RESTORE_FILES.txt
    Folder: C:\c2e697b
    Folder: C:\ProgramData\{18165758-115C-4DC0-9EC2-FF89F725767F}
    2015-05-05 13:51 - 2014-10-21 12:54 - 00000000 ___HD () C:\ProgramData\{9A88E103-A20A-4EA5-8636-C73B709A5BF8}
    2014-10-22 15:36 - 2014-10-22 15:36 - 0000448 ____H () C:\Users\Robert Buss\AppData\Roaming\麽鎒駓覜
    2014-10-22 15:36 - 2014-10-22 15:36 - 0000944 ____H () C:\ProgramData\@system2.att
    2014-10-22 15:37 - 2014-10-22 15:37 - 0087200 _____ () C:\ProgramData\wrnhoah.tmp
    C:\Users\Robert Buss\AppData\Local\Temp\install_flashplayer16x32axau_mssa_aaa_aih.exe
    2014-11-04 20:09 - 2014-11-04 20:09 - 0026572 _____ () C:\ProgramData\xportnchk.ini
    Task: {DAD2BBAC-F8E3-4540-BAD3-289F0551A804} - System32\Tasks\{C115EE76-3ABF-1883-FF0F-A346BDCBAF87} => C:\windows\system32\yhksot.dll [2014-10-25] ()
    C:\windows\system32\yhksot.dll
    2015-04-21 08:33 - 2015-05-13 18:52 - 00000678 _____ () C:\windows\Tasks\Windows Updates.job
    2015-04-21 08:33 - 2015-05-13 18:48 - 00003644 _____ () C:\windows\System32\Tasks\Windows Updates
    2015-04-21 08:33 - 2015-04-21 08:33 - 00003756 _____ () C:\windows\System32\Tasks\GoogleUpdater
    Task: {0608A7B7-A6D5-4D8C-8F24-0AC7F3976206} - System32\Tasks\Windows Updates => C:\Windows\syswow64\windowspowershell\v1.0\powershell.exe [2009-07-13] (Microsoft Corporation)
    Task: C:\windows\Tasks\Windows Updates.job => C:\Windows\syswow64\windowspowershell\v1.0\powershell.exeË-windowstyle hidden -noninteractive -command $a = New-Object System.Net.WebClient; $b = $a.Dow
    CustomCLSID: HKU\S-1-5-21-4221278862-339456626-841341803-1001_Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32 -> No File
    Task: {27639465-36F0-448C-B279-A805CC7F438E} - System32\Tasks\GoogleUpdater => Rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";document.write((new%20ActiveXObject("WScript.Shell")).RegRead("HKCU\\software\\microsoft\\internet explorer\\zergling_rush"))
    Task: {8A5F7EDA-969C-485B-9AA5-30E711D1A0A7} - System32\Tasks\{F039642D-AA0B-47A8-8A95-DBDD2097A1EC} => pcalua.exe -a "C:\Program Files (x86)\weDownload Manager\Uninstall.exe" -c /fromcontrolpanel=1
    reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^Robert Buss^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MyPC Backup.lnk" /f
    C:\windows\pss\MyPC Backup.lnk.Startup
    reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CouponXplorer Home Page Guard 64 bit" /f
    C:\PROGRA~2\COUPON~2
    reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ShopAtHomeUpdater" /f
    reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ShopAtHomeWatcher" /f
    C:\Users\Robert Buss\AppData\Roaming\ShopAtHome
    reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\VideoDownloadConverter Home Page Guard 64 bit" /f
    C:\PROGRA~2\VIDEOD~2
    reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\{cea133f5-521a-b4f6-01e8-7faf82dbda25}" /f
    C:\Users\Robert Buss\AppData\Local\Microsoft\{cea133f5-521a-b4f6-01e8-7faf82dbda25}
    CMD: ipconfig /flushdns
    EmptyTemp:
    end
  • Click File, Save As and type fixlist.txt as the File Name. 
  • Important: The file must be saved in the same location as FRST64.exe. 
  • Important: In the Encoding: drop-down box, select Unicode.

NOTICE: This script is intended for use on this particular machine. Do not use this script on any other machine; doing so may cause damage to your Operating System.

  • Right-Click FRST64.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Click Fix.
  • A log (Fixlog.txt) will open on your desktop. Copy the contents of the log and paste in your next reply.
     

STEP 2
[external image: nSymGHK.png] Folder Options 

  • Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type Control Folders and click OK.
  • Click View. Under Hidden files and folders: 
  • Place a checkmark next to Show hidden files, folders and drives.
  • Remove the checkmark next to Hide extensions for known file types.
  • Remove the checkmark next to Hide protected operating system Files (Recommended).
  • Click Apply followed by OK.
     

STEP 3
[external image: nWhGEI3.png] VirusTotal Upload

  • Please go to VirusTotal.com.
  • Click Choose File and locate the following file:
    • C:\Users\Robert Buss\AppData\Roaming\ChromeUpdate.exe
  • ​Click Scan it!.
  • If you receive the following notification: File already analysed click Reanalyse.
  • Once the file has been analyzed, copy the page URL at the top of the window and paste in your next reply. 
  • Please do the same for the files below:
    • C:\windows\system32\Drivers\psaftshf.sys
       

======================================================
 
STEP 4
[external image: xpfNZP4A.png.pagespeed.ic.bp5cRl1pJg.jpg] Logs
In your next reply please include the following logs. Please be sure to copy and paste the requested logs, as well as provide information on any questions I may have asked.

  • Do you recognise the items in the spoiler?
  • Fixlog.txt
  • VirusTotal results

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI